Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What is the ISO 27001 certification process?

Last verified

The ISO/IEC 27001 process is Stage 1 (documentation and readiness), Stage 2 (implementation and effectiveness), then a typical three-year certificate with surveillance and later recertification. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.

Audit-cycle explainer, last verified 10 September 2026. ISO 27001 is a voluntary standard, not a law. The certification body is audited against ISO/IEC 17021-1 and ISO/IEC 27006; IAF MD 5 influences duration. Clauses 4–10 are what get certified; Annex A is selected via the SoA.

What this page is, and what it is not

Audience: a CISO or compliance owner preparing for the accredited audit, not a first-time “what is ISO” reader.

This page is not legal advice. It does not determine YOUR obligations, does not start a clock, and does not file a certification application. Last verified 10 September 2026.

Only an IAF-MLA accredited certification body issues a recognised certificate. An unaccredited PDF is not the same artefact. This product does not issue certificates.

Stage 1, Stage 2, and the years that follow

Typical outputs are illustrative. Your certification body plans the sample. Last verified 10 September 2026. Not legal advice.

Certification stages and typical outputs (illustrative; not a quote; not legal advice; last verified 10 September 2026)
StageWhat the auditor reviewsTypical outputKind of text
Stage 1 — documentation / readinessScope, policy, risk assessment and treatment, SoA, documented information required by Clauses 4–10, whether you appear ready for Stage 2.A Stage 1 report. Findings that must be closed before Stage 2, or a planned Stage 2 date.ISO/IEC 17021-1 / ISO/IEC 27006 audit practice against ISO/IEC 27001.
Stage 2 — implementation / effectivenessWhether the ISMS operates as documented. Sample of Annex A controls marked implemented. Internal audit and management review evidence.A Stage 2 report. Recommendation to certify, or nonconformities to close first.Same audit standards. Not a SOC 2 opinion.
Major nonconformityA breakdown of the ISMS or a requirement not met that casts doubt on the system’s ability to achieve its outcomes.Corrective action, often blocking certificate issuance until closed.Certification-body grading practice under 17021-1 — paraphrased, not quoted.
Minor nonconformityA requirement not fully met that does not, by itself, indicate ISMS failure.Corrective action on an agreed timeline; certificate may still issue.Certification-body grading practice.
Certificate issuanceDecision by the certification body after Stage 2 (and any required closures).A certificate typically valid three years, subject to surveillance.Accredited certification outcome. Not a law.
Surveillance (usually years 1 and 2)Partial sample of the ISMS — not a full recertification.Continued validity, or findings.17021-1 surveillance requirements. See the surveillance page in this cluster.
Recertification (before expiry)Full reassessment of the ISMS.A new cycle, or a lapse if you miss the window.17021-1 recertification. See the recertification page.

Corrective actions and who decides

The certification body grades findings and decides whether to issue or continue the certificate. Consultants, tooling, and this product do not. A major nonconformity typically delays issuance until the cause is corrected and verified. Last verified 10 September 2026. Not legal advice.

Checklist

Use this as the checklist artifact before Stage 1. Last verified 10 September 2026. Not legal advice.

  • Is the certification body listed in IAF CertSearch for ISO/IEC 27001, under an IAF-MLA accreditation body (UKAS, ANAB, or peer)?
  • Are Stage 1 and Stage 2 scheduled as two stages, not one blended “audit day” that skips readiness?
  • Can we show scope, policy, risk records, SoA, internal audit, and management review as documented information?
  • Do we understand major vs minor nonconformity as the body’s grades, not as a product score?
  • Have we planned surveillance in years 1 and 2 and recertification before the typical three-year expiry?
  • Have we accepted that IAF MD 5 influences audit days, so calendar time is not a vendor marketing number?

What to do now

These steps do not file an application and do not start a clock.

  • Verify the body’s accreditation before you sign a proposal.
  • Treat Stage 1 as a readiness gate, not as “the audit.”
  • Close documented-information gaps before Stage 2.
  • Read the surveillance and recertification pages so the three-year cycle is visible to finance.
  • Keep a corrective-action log that a Stage 2 auditor can sample.

Where this shows up in ShipReady Metrics

Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.

If you already have a session: signed-in app → Compliance evidence collection and evidence review (met-verdict overlay) help assemble the Stage 2 package. The obligation map, policies library, and cyber risk register hold scoping and artefacts. ISO 27001 is in the 24-framework library; Annex A is crosswalked to about 72 canonical controls with a crosswalk-density honesty layer — coverage, not a pass.

The certification decision remains the accredited body’s.

Primary sources (last verified 10 September 2026)

ISO/IEC 27001:2022; ISO/IEC 17021-1; ISO/IEC 27006; IAF and IAF MD 5. This page paraphrases audit-cycle practice and does not quote paywalled clause text. Not legal advice.

Frequently asked questions